PT-2009-3825 · Tibco · Tibco Enterprise Message Service+2
Published
2009-04-30
·
Updated
2017-08-17
·
CVE-2009-1291
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TIBCO SmartSockets versions prior to 6.8.2
TIBCO SmartSockets Product Family (aka RTworks) versions prior to 4.0.5
TIBCO Enterprise Message Service (EMS) versions 4.0.0 through 5.1.1
Description
The issue allows remote attackers to execute arbitrary code via inbound data. This can be demonstrated by requests to the UDP interface of the RTserver component and data injection into the TCP stream to tibemsd.
Recommendations
For TIBCO SmartSockets versions prior to 6.8.2, update to version 6.8.2 or later.
For TIBCO SmartSockets Product Family (aka RTworks) versions prior to 4.0.5, update to version 4.0.5 or later.
For TIBCO Enterprise Message Service (EMS) versions 4.0.0 through 5.1.1, update to a version outside of this range.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tibco Enterprise Message Service
Tibco Smartsockets
Tibco Smartsockets Product Family